Classify every AI system against Annex III. Generate Annex IV technical documentation. Run the Article 27 impact assessment. Track the deadlines the Digital Omnibus moved — all in one workspace.
Who must comply
Providers, deployers, importers and distributors of AI systems used in the EU
Key dates
Prohibitions since 2 Feb 2025 · GPAI since 2 Aug 2025 · Annex III high-risk from 2 Dec 2027
Maximum fines
Up to €35M or 7% of global annual turnover
Dates follow Regulation (EU) 2024/1689 as amended by the Digital Omnibus, Regulation (EU) 2026/1744. It was published on 24 July 2026 and is in force since 27 July 2026. Article 50 transparency was not deferred: it applies since 2 August 2026. This is guidance, not legal advice. Confirm your position with counsel.
Obligations follow the risk class of the system and your role in the supply chain. The four duties that drive most of the work:
Every AI system is prohibited, high-risk, limited-risk or minimal-risk. Annex III lists the eight high-risk use areas. Article 6(3) lets you rebut high-risk status, but only with documented reasoning you keep on file.
A risk-management system, data governance, technical documentation, automatic logging, instructions for deployers and human oversight. Plus accuracy, robustness and cybersecurity. Each one has to be evidenced, not asserted.
Run the conformity assessment before the system goes on the market. Draw up the EU declaration of conformity and affix the CE marking. Then register the system in the EU database.
Tell people when they interact with AI. Mark synthetic content. Monitor the system after it goes live. Report serious incidents to the market surveillance authority.
One inventory of your AI systems drives the classification, the documentation and the evidence — so the same facts are never entered twice.
A guided questionnaire walks each system through the eight Annex III areas and the Article 6(3) exception. The reasoning is stored in an audit log that cannot be edited.
Generate Article 11 technical documentation from the system record you already maintain. It is versioned, exportable, and available in English, Italian, German and French.
The Article 27 fundamental rights impact assessment reuses your existing data protection impact assessments. You do not answer the same questions twice.
The compliance timeline follows the amended dates. Annex III high-risk from 2 December 2027. Embedded high-risk from 2 August 2028. Article 50 transparency has been live since 2 August 2026.
Providers who place an AI system on the EU market. Deployers who use one under their own authority. Importers and distributors who bring it in. It applies even if you are established outside the EU, as long as the system or its output is used here.
Prohibited practices and AI literacy since 2 February 2025. General-purpose AI model rules and penalties since 2 August 2025. Article 50 transparency since 2 August 2026. Standalone Annex III high-risk obligations from 2 December 2027. High-risk AI embedded in regulated products from 2 August 2028.
Start with Annex III. It lists eight areas: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and border control, and justice. If your use falls in one, the system is high-risk. You can rebut that only by documenting no significant risk under Article 6(3).
Up to €35 million or 7% of worldwide annual turnover for a prohibited practice. Up to €15 million or 3% for breaching most other obligations. Up to €7.5 million or 1% for giving authorities incorrect, incomplete or misleading information. The higher of the two figures applies to undertakings.
Yes. Chapter V has applied since 2 August 2025. Providers of general-purpose AI models keep technical documentation, publish a summary of the training content and follow a copyright policy. Models with systemic risk also run evaluations and report serious incidents.
Take the free self-assessment and get a readiness report with your risk level and the obligations that apply to you.